Privacy Policy
Last updated 16 August 2026. What we store, why, and how to get rid of it.
The short version
Meneldur is built to know as little about you as possible. There is no account by default, no password, no profile, and no advertising. We do not sell or share your data, and we do not run third-party trackers or advertising pixels.
For data protection purposes, Meneldur is the data controller for the information described below. Contact us about anything on this page at hello@meneldur.com.
What we store
- An anonymous browser key. When you start a trial we generate a random key and put it in an httpOnly cookie. It identifies a browser, not a person. It is what your trial, subscription and saved companies hang off. We cannot tell who you are from it.
- Your email address, only if you give it. Supplying one is optional and exists so you can move your access to another browser via a sign-in link. We store the address, and a hash of each sign-in token — never the token itself, so a copy of our database does not let anyone sign in as you.
- Billing identifiers, if you subscribe. Stripe handles the payment and gives us a customer and subscription id plus the status and renewal date. We never receive or store your card number.
- Your saved companies. Which companies you kept or dismissed, attached to the browser key.
- A Telegram chat id, if you use the alerts bot. Only so alerts can be delivered to you.
- The IP address of a sign-in request, kept with the token so the sign-in endpoint can be rate limited against abuse.
We do not collect your name, address, date of birth, phone number, or any financial account details. We do not know what you own or what you trade — Meneldur has no portfolio feature and never asks.
Why we store it, and on what legal basis
To run the service you asked for: to know whether your trial is live or your subscription is paid, to send a sign-in link when you request one, to deliver alerts you subscribed to, and to keep your saved list between visits. That is the whole list. We do not profile you and we do not build audiences.
Under the UK and EU GDPR every use of your data needs a lawful basis. Ours are:
- Performance of a contract (Art. 6(1)(b)) — the browser key, the subscription status and the saved companies. Without these there is no service to provide.
- Consent (Art. 6(1)(a)) — your email address and the Telegram chat id. Both are optional, both are given by you to receive something specific, and you can withdraw either at any time by asking us to delete it or by stopping the bot.
- Legal obligation (Art. 6(1)(c)) — records tied to payments, which tax and accounting rules require us to keep for a period after they are made.
- Legitimate interests (Art. 6(1)(f)) — the IP address stored with a sign-in request, kept only to rate limit that endpoint. Our interest is preventing abuse of a link that grants access; the data is narrow, short-lived, and used for nothing else.
There is no automated decision-making that produces legal or similarly significant effects for you. The valuation verdicts are calculations about companies, not about you.
Who else sees it
Only the services needed to run the product, and only what each one needs:
- Stripe — payment processing. They receive your card and billing details directly; we do not see them.
- Resend — sends sign-in and alert emails, so it processes your email address.
- Telegram — only if you start the alerts bot, and only your chat id.
- Railway — hosts the application and database.
We do not sell your data, rent it, or hand it to advertisers. We would disclose it if legally compelled to.
Transfers outside the UK and EEA. Some of these providers are based in, or store data in, the United States. Where that happens the transfer relies on the safeguards those providers put in place — standard contractual clauses, and where applicable the EU–US Data Privacy Framework. You can ask us which safeguard applies to a particular provider.
Cookies
One cookie, and it is not optional because it is the service: the anonymous key that carries your trial or subscription. It is httpOnly, so scripts on the page cannot read it. There are no analytics, advertising or tracking cookies, which is why you are not being asked to accept anything.
How long we keep it
- Sign-in tokens — minutes. They expire quickly and are single use; the stored value is a hash, never the token.
- Browser key, saved companies, email, Telegram chat id — while your access is active, and up to 12 months afterwards so a returning subscriber finds their list intact. Deleted sooner on request.
- Payment records — kept as long as tax and accounting rules require, typically six to seven years. These we cannot delete on request, because keeping them is a legal obligation.
Your rights
If the UK or EU GDPR applies to you, you have the right to:
- Access — get a copy of the data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have it deleted, except where we are legally required to keep it.
- Restriction — have us pause processing while a dispute is resolved.
- Portability — receive your data in a machine-readable form.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — at any time, for anything given on that basis. Withdrawing does not affect what was lawful before.
We will respond within one month. Exercising these rights is free unless a request is manifestly unfounded or excessive.
Because the identifier is an anonymous browser key, we may need you to send the request from the browser holding it, or from the email address attached to it, before we can act — otherwise we would be handing one person another person’s data on request. That check is a safeguard for you, not an obstacle.
To exercise any of these, write to hello@meneldur.com. If you are unhappy with how we handle it, you can complain to your national data protection authority — in the UK the Information Commissioner’s Office, and in the EU the supervisory authority for the country you live in.
Changes
If this policy changes, the date at the top changes with it. Material changes to what we collect will be announced in the app rather than only here.
Written in plain language and not a substitute for legal advice. Two things a lawyer should confirm before relying on this: that a data processing agreement is in place with each provider listed above, and whether the controller must be identified here by registered entity name and postal address rather than by trading name alone. See also the terms of service.